Lucene search

K
cvelistTwcertCVELIST:CVE-2022-39060
HistoryJan 31, 2023 - 12:00 a.m.

CVE-2022-39060 ChangingTec MegaServiSignAdapter - Improper Input Validation

2023-01-3100:00:00
CWE-20
twcert
www.cve.org
5
changingtech megaservisignadapter
input validation
registry access
vulnerability
remote attack

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.8

Confidence

High

EPSS

0.003

Percentile

71.1%

ChangingTech MegaServiSignAdapter component has a vulnerability of improper input validation. An unauthenticated remote attacker can exploit this vulnerability to access and modify HKEY_CURRENT_USER subkey (ex: AutoRUN) in Registry where malicious scripts can be executed to take control of the system or to terminate the service.

CNA Affected

[
  {
    "vendor": "ChangingTec",
    "product": "MegaServiSignAdapter",
    "versions": [
      {
        "version": "1.0.17.0823",
        "status": "affected"
      }
    ],
    "platforms": [
      "Windows"
    ]
  }
]

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.8

Confidence

High

EPSS

0.003

Percentile

71.1%

Related for CVELIST:CVE-2022-39060